Critical TP-Link Archer Flaws Let Attackers Inject Commands
Key Takeaways TP-Link has addressed three high-severity command injection vulnerabilities across multiple Archer router models. The flaws, including one unauthenticated vulnerability, could allow...
Key Takeaways
- TP-Link has addressed three high-severity command injection vulnerabilities across multiple Archer router models.
- The flaws, including one unauthenticated vulnerability, could allow attackers to execute arbitrary commands with root privileges.
- Affected models include Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1.
- Firmware updates are available, and users are strongly advised to apply them immediately.
TP-Link has issued a critical security advisory concerning three high-severity command injection vulnerabilities impacting several models in its Archer router series. These security flaws, if exploited, could grant nearby attackers root-level access, leading to complete device compromise and potential further attacks on devices within the local network.
Table Of Content
The vulnerabilities, detailed in a security advisory updated on August 24, 2026, are identified as CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541. TP-Link has promptly released firmware updates for all affected products and is urging customers to install these patches without delay.
Unauthenticated Command Injection in Parental Controls (CVE-2026-9254)
The most severe of the disclosed issues is CVE-2026-9254, an unauthenticated operating-system command-injection vulnerability present in the parental control function of Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 devices. This flaw stems from inadequate filtering and neutralization of special characters within specific parameters.
An attacker operating on the local network could exploit this vulnerability without needing to authenticate or log into the router. Successful exploitation would enable the injection and execution of arbitrary system commands as the root user, granting the attacker the highest possible privilege level on the device. This issue has been assigned a CVSS v4.0 score of 8.7, categorizing it as High severity. TP-Link warns that exploitation could severely impact the confidentiality, integrity, and availability of both the router and all network traffic.
Authenticated Command Injection in VPN Functionality (CVE-2026-16348)
The second vulnerability, CVE-2026-16348, affects the VPN connection feature specifically on Archer BE800 V1 routers. This is an authenticated command injection flaw, meaning it requires administrative access for exploitation. An attacker with valid administrator credentials could inject shell metacharacters through a VPN connection, subsequently executing commands with root privileges. Despite the requirement for prior authentication, the potential impact remains significant.
Successful attacks could allow threat actors to establish persistent backdoors, steal sensitive credentials, perform reconnaissance on the local network, and leverage the compromised router to target other connected systems. CVE-2026-16348 carries a CVSS v4.0 score of 8.5, also rated as High severity.
Stored Command Injection via Parental-Control Profile Names (CVE-2026-78541)
The third identified flaw, CVE-2026-78541, is a stored command injection vulnerability found in the parental control module of Archer BE3600 V1 routers. An authenticated attacker possessing administrative access can craft a malicious profile name containing shell metacharacters. This harmful input is then stored on the device and may be processed unsafely at a later stage, specifically when the router generates its daily cloud report. This delayed execution path can result in arbitrary commands being run on the router.
TP-Link assigned this vulnerability a CVSS v4.0 score of 8.5. The following table summarizes the vulnerabilities and corresponding fixed firmware versions:
| CVE | Vulnerability | Affected Product | Fixed Firmware | CVSS |
|---|---|---|---|---|
| CVE-2026-9254 | Unauthenticated OS command injection in parental controls | Archer BE800, BE3600, AX75 | BE800: 1.4.2 Build 260708; BE3600: 1.2.6 Build 20260617; AX75: 1.1.6 Build 260716 | 8.7 |
| CVE-2026-16348 | Authenticated command injection in VPN functionality | Archer BE800 | 1.4.2 Build 260708 | 8.5 |
| CVE-2026-78541 | Stored OS command injection via parental-control profile names | Archer BE3600 | 1.2.6 Build 20260617 | 8.5 |
What You Should Do
- Immediately download and install the newest firmware updates from TP-Link’s official regional support pages for your specific router model.
- Before updating, verify the installed hardware revision of your router to ensure you are applying the correct firmware.
- Change any default administrator credentials on your router to strong, unique passwords.
- Restrict router administration access to only trusted devices within your network.
- Disable any remote management services that are not strictly necessary.
- Regularly monitor network logs for any unusual configuration changes or unexpected outbound traffic patterns.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.